Close Menu
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Trending

Conflicts: HumAngle trains Benue journalists on solutions, data journalism

September 22, 2026

Collins aide dismisses corruption allegation as ‘categorically false’

September 22, 2026

Earl Spencer apologises to Piers Morgan over ‘incorrect assumption’ | Diana, Princess of Wales

September 22, 2026
Facebook X (Twitter) Instagram
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Subscribe
Web StatWeb Stat
Home»AI Fake News
AI Fake News

Beware these fake websites selling subscriptions to AI assistants – Computerworld

News RoomBy News RoomSeptember 22, 2026Updated:September 22, 202611 Mins Read
Facebook Twitter Pinterest WhatsApp Telegram Email LinkedIn Tumblr

Imagine a cybercriminal who wants to build a convincing fake subscription site. Gone are the days of hand-coding HTML or buying a domain and hoping for the best. According to researchers at Malwarebytes, a growing number of scams are powered by a legitimate commercial website creation kit. This is not a stealthy cybercrime toolkit from the dark web; it is an ordinary product anyone can buy, with familiar features such as account management, billing, file storage and administrative controls. The company behind it says even a complete beginner can launch a website within an hour. After a one-time purchase, extra templates cost only about $2 each. For a criminal, that is an outrageous bargain. A scammer can spin up dozens of professional-looking pages for less than the price of a coffee. The fake pages are not ugly or static; they look like polished tech start-ups. This is the first layer of deception. The website builder is not malicious in itself—it is a tool, like a printing press. But in the hands of scammers, it becomes a factory for fake AI services. The victims are people who are curious about artificial-intelligence tools and willing to pay for a subscription to try them. They arrive through search results, social media ads or phishing emails, and nothing immediately screams “scam.” The design is clean, the logos are plausible, and the sign-in button seems to work as expected. It is only after handing over an email address, a password and perhaps credit-card details that the trouble begins. But the real deception is far sneakier than a typical phishing page, because the password theft is not a password theft at all from the user’s perspective. It is a carefully orchestrated abuse of Google’s own sign-in system, and that is what makes it so dangerous.

The second layer is where the trick gets clever. On these fake websites, visitors are not presented with a fake password form asking them to type a Gmail password into a box on the site. That would be too easy to spot: the URL would be wrong, the design might be off, and attentive users would check the address bar. Instead, the fake sites use genuine Google sign-in pages. When you click “Sign in with Google,” you are actually taken to Google’s official login page. You enter your credentials on Google’s website. The password field belongs to Google. The SSL certificate is valid. The URL reads accounts.google.com. From a security perspective, the user is doing exactly what Google intends: authenticating safely. But the trick is in what happens after Google verifies who you are. The fake application requests access to basic information from your Google account—specifically, your name, email address and profile picture. That is it. The malicious apps Malwarebytes examined did not request access to Gmail or Google Drive, which might have set off alarm bells. They asked for the minimal amount of data that would make the sign-in feel real and useful. For a supposed AI service, asking for a name and email to create an account is completely normal. The user thinks they are signing up for a tool; in reality, they are granting an unknown third-party application permission to access a slice of their identity. Because the OAuth flow is legitimate, the browser has no reason to warn the user. The page is safe. The login is safe. The request for basic profile data is displayed by Google itself. But the intent behind it is not safe. The criminals are using Google’s own trust mechanisms against the people they are targeting. They do not need to steal passwords because they can get something more valuable—an authorized connection to a Google account, plus money from a fake subscription. And because the user voluntarily entered a password into Google’s real site, they may never think to double-check what they approved. That is the uncomfortable truth about modern phishing: sometimes the password is not the target.

Malwarebytes, which has been tracking these operations, points to a specific red flag that most victims probably miss. Google’s consent screen—the page that appears after you log in and asks whether to allow an application to access your account—normally identifies the application and provides the developer’s contact details. Legitimate developers list a company name and a support email or website. On the fake websites studied by Malwarebytes, however, that consent screen displayed free webmail addresses for developer contacts. Think about that for a moment. A supposed AI service good enough to sell subscriptions, with a professional website and a Google sign-in flow, apparently uses a Gmail address or a Yahoo address as its developer contact. Not an email from its own domain, but a free webmail account. That is a massive red flag, yet it is easy to overlook in the heat of the moment. The user is trying to get access to an AI tool. Maybe they saw an impressive demo online. They click, they log in with Google, and they are presented with a permissions screen full of technical jargon. Most people do not read those screens carefully. They see the name of the app, which matches the website they came from, and click “Allow.” But if they paused and scrolled down, they would see the developer contact. Instead of an address matching the brand, they would see something like “[email protected].” That mismatch tells you the app is not operated by the well-known AI company whose logo is on the site. In the case of unfamiliar AI brands—services you have never heard of—the situation is even worse. The websites provide little independently verifiable information about the businesses behind them. There is no physical address, no established corporate history, no credible track record. There is just a shiny site and a vague promise of AI-powered magic. The consent screen’s free webmail contact is one of the few hard facts available, and it is a clue that the operation is amateurish at best and criminal at worst.

Let’s talk about those unfamiliar AI brands, because they are a key part of the story. The researchers found that the fake sites fell into two categories. Some pretended to be well-known AI services, using the name and logo of a company people already trust. These are easy to understand: the scammer trades on brand recognition. But other sites are not pretending to be a famous tool at all. They are unknown AI brands—made-up names, made-up features, made-up promises. On the surface, this seems like a less effective scam. Would anyone pay for an AI service they have never heard of? Apparently, yes. The websites are designed to make the unfamiliar seem familiar. They contain all the typical elements of a modern tech product page: a hero image, a list of impressive features, some fake testimonials, a pricing table with buttons that say “Get Started” or “Start Free Trial.” They may even have blog posts and social media links, though those links usually lead to dead ends or accounts with no real followers. For a user, the absence of verifiable information is a warning sign, but people do not always look. They are too focused on the product itself. The promise of AI-generated content, automated image editing, intelligent writing assistance, or some other shiny capability is enough to make them ignore the missing details. Malwarebytes noted that these sites provide little independently verifiable information about the businesses selling the subscriptions. That phrase is crucial. Anyone can put text on a website. Anyone can claim to have been founded in 2018 or to have thousands of happy customers. What is hard to fake is a paper trail—business registrations, corporate addresses, press coverage, app-store listings, patents, employee profiles, or a consistent social-media presence. The fake AI brands have none of that. They exist only as a single website tied to the legitimate-but-anonymous website builder. If you try to look them up, you find nothing. And nothing, in this context, is exactly what the scammers want. They do not need a real company because they do not intend to provide a service. They intend to collect credit-card payments and walk away, or harvest enough data to use later. For them, the website is not a product; it is a trap.

So what does the victim actually lose? First, money. They sign up for what they think is a paid subscription. The pricing page encourages them to choose a plan, enter credit-card details, and confirm the purchase. The scammers collect those payments through the website builder’s billing functionality—again, a legitimate commercial feature used for illegitimate purposes. The card is charged, but no service ever materializes, or the service turns out to be a dummy feature that does nothing. Second, they hand over a piece of digital identity. By approving Google sign-in, they give the malicious application access to their name, email address and profile picture. That might sound harmless, but consider what someone could do with that information. An email address is the key to a person’s online life. Combined with a name and photo, it can be used for targeted phishing, account-recovery attacks, or identity fraud. The scammers now have a verified connection to a real, active Google account. They also know the owner is interested in AI tools and willing to pay for online services—an appealing profile for further exploitation. Third, the victim loses trust. After being taken by a fake AI startup, they may become more suspicious of legitimate online services. That mistrust has a real cost, making it harder for honest developers to gain users. It is a ripple effect that goes far beyond the individual scam. The researchers at Malwarebytes did not speculate about all these consequences, but they are easy to infer. What they did note is that the operation is far more subtle than the average phishing campaign. There are no “your account has been locked” emails, no “click here to update your password” links, no fake login pages at odd URLs. It uses Google’s actual infrastructure to create a sense of security. Because the user is physically typing their password into Google’s official login page, neither the user nor Google can easily tell that something is off. The malicious part is not the login; it is the application approval and the payment. By the time the user understands that, the damage is already done.

What can you do to avoid falling for this? First, always check the consent screen before allowing any third-party app to use your Google account. Look at the developer’s contact information. If it is a free webmail address rather than a domain that matches the service, refuse. Second, research any AI service before giving it money or access. Search for reviews, look for independent coverage, check the company’s website, and see if the business has a real presence beyond a single web page. If you cannot find anything, that is your answer. Third, be suspicious of any service that promises the moon at a steep discount. The scammers rely on people’s eagerness to test new technology. By slowing down and thinking critically, you can spot the signs. Fourth, periodically review the third-party apps connected to your Google account. Google has a page for this, and it is a good habit to check it every few months. Revoke access to anything you do not recognize or no longer use. Finally, use a credit card, not a debit card, for online purchases; if you are charged for a service you never received, you have better fraud protection. The larger lesson is that phishing is no longer just about fake login pages. It is about abusing legitimate tools—Google’s sign-in infrastructure, commercial website builders, standard billing platforms—to construct a convincing illusion. The attackers are not hacking your password; they are hacking your judgment. They show you a real Google login to make you think the website is legitimate. They show you a professional design to make you think the company is credible. They show you a modest price to make you think the subscription is harmless. Because each individual piece is real, the illusion holds together. The best defense is not technical; it is skepticism and mindfulness. Before you click, ask yourself: Do I actually know what this app is? Does this permission make sense? Can I verify that the developers are who they claim to be? If the answers do not come easily, walk away. There will always be another AI tool to try tomorrow—but there will not always be another chance to take back your money, your data, and your trust.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News Room
  • Website

Keep Reading

Trump rebrands Artificial Intelligence to Super Intelligence

Beware these fake websites selling subscriptions to AI assistants

Zelda Williams tells AI deepfake creators to ‘have some shame’ over fake Robin Williams clip

A Highly Trafficked Space News Site Invented a Fake NASA Engineer and Used Her Name to Publish to AI-Generated Slop

Local city warns of AI fake property video scam – WHIO TV

Tasmanian justice department review under way after AI and fake citation used in murderer’s parole decision | Tasmania

Editors Picks

Collins aide dismisses corruption allegation as ‘categorically false’

September 22, 2026

Earl Spencer apologises to Piers Morgan over ‘incorrect assumption’ | Diana, Princess of Wales

September 22, 2026

Gulfport town hall tackles dengue concerns and misinformation

September 22, 2026

U of A, library team up to squash GLP-1 misinformation – CTV News

September 22, 2026

Vansh Bedi denies links to match-fixing in DPL, calls reports “false and defamatory”

September 22, 2026

Latest Articles

Trump rebrands Artificial Intelligence to Super Intelligence

September 22, 2026

‘False and defamatory’: Vansh Bedi denies being unnamed man in fixing, information leak sting

September 22, 2026

AI-generated fake results, deepfakes could fuel 2027 election misinformation

September 22, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Facebook X (Twitter) Pinterest TikTok Instagram
Copyright © 2026 Web Stat. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.